how to update mobian over tor
#11
How can we trust those TOR links not to contain malware? I would recommend HTTPS instead, failing that HTTP, but not TOR with Onion links given by some random commenter on some forum.
  Reply
#12
(07-09-2023, 05:40 AM)Kevin Kofler Wrote: How can we trust those TOR links not to contain malware? I would recommend HTTPS instead, failing that HTTP, but not TOR with Onion links given by some random commenter on some forum.

we should be suspicious of tor links. however, if signing keys are properly validated, then installer won't install those altered packages.

this creates another problem, where are signing keys from!? do users check signing keys!?

btw, http (non-ssl) could be hijacked in rare cases.
  Reply
#13
(07-09-2023, 03:27 PM)zetabeta Wrote: btw, http (non-ssl) could be hijacked in rare cases.
Which is why I recommend HTTPS if possible. But Debian has this strange idea of still defaulting to unencrypted HTTP mirrors in 2023 and requiring a subpackage to be installed for APT to support HTTPS at all.
  Reply
#14
(07-09-2023, 05:40 AM)Kevin Kofler Wrote: How can we trust those TOR links not to contain malware? I would recommend HTTPS instead, failing that HTTP, but not TOR with Onion links given by some random commenter on some forum.

links not random not suspicious. all  .onion  links in this thread are official debian mirrors https://onion.debian.org  as zetabeta says, non official mirrors okay if signing keys are properly validated, then installer won't install those altered packages.  But all onion links in this thread are official debian mirrors https://onion.debian.org

sub packages no longer need to be installed for apt transport https support
  Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Mobian repository status henrythemouse 16 8,582 04-10-2024, 10:02 AM
Last Post: diederik
  bookworm vs trixie discussion for mobian in pinephone regular. zetabeta 15 1,857 03-25-2024, 09:07 AM
Last Post: anonymous
  cant verify mobian image at website gnugpg penguins_rule 0 116 03-18-2024, 08:54 PM
Last Post: penguins_rule
  mobian installed to eMMC - how to install tow-boot grump_fiddle_reinstall 6 1,901 11-22-2023, 11:46 AM
Last Post: aLoop100o
  What actions needed to keep on mobian testing user641 3 1,771 09-05-2023, 06:44 AM
Last Post: Zebulon Walton
  Mobian boot failed with zstd message after upgrade. Mahgue 0 617 09-01-2023, 11:29 AM
Last Post: Mahgue
  opensnitch outbound firewall now works on mobian vusra 2 1,875 07-09-2023, 01:37 AM
Last Post: vusra
  Using Nativefier on PP64 with Mobian paulcarton 0 615 07-05-2023, 03:57 AM
Last Post: paulcarton
  Has anyone got briar-desktop running on mobian? vusra 5 2,967 06-19-2023, 03:02 PM
Last Post: vusra
  Wifi doesn't work after update nickolas 2 1,208 04-14-2023, 10:07 AM
Last Post: nickolas

Forum Jump:


Users browsing this thread: 1 Guest(s)